Add workflow permissions #26
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Potential fix for https://github.com/microsoft/stackfuture/security/code-scanning/2
To address this issue, we should add the minimal required
permissionskey to the workflow. Since neither thebuildnor themirijob requires anything beyond reading repository contents (for checking out code to build/test), we setcontents: readas the global permissions. The most efficient and maintainable fix is to add thepermissionsproperty at the root of the workflow file (just after thename:and before the jobs section), so it applies to all jobs. No changes to imports or job steps are needed.Specifically, edit
.github/workflows/rust.yml:permissions:block directly after thename: Rustline, prior to theon:block.contents: readwithin this block.No other code, imports, methods, or definitions are required for this correction.
Suggested fixes powered by Copilot Autofix. Review carefully before merging.